---
title: "๐ก๏ธ Ring2All SBC (Session Border Controller) Deployment Guide"
description: "Step-by-step installation and deployment guide for Ring2All SBC (Kamailio 6.1, RTPEngine 12.5, WireGuard Mesh) on Debian 13"
---
> Complete step-by-step guide for installing and configuring **Ring2All SBC** on Debian 13 (Trixie), shielding your core telephony cluster with perimeter security, NAT traversal, and encrypted WireGuard mesh.
---
## ๐๏ธ Architecture Overview
The **Ring2All SBC (Session Border Controller)** serves as the hardened security perimeter between untrusted public networks (internet subscribers, remote softphones, PSTN carrier trunks) and your private core telephony cluster (Ring2All PBX nodes).
```mermaid
flowchart TB
subgraph PublicInternet["Public Internet & Carrier Networks"]
Subscribers["Remote SIP & WebRTC Clients
(Hardphones, Softphones, Mobile Apps)"]
Carriers["Upstream PSTN Carrier Trunks
(Inbound DIDs & Outbound Termination)"]
end
subgraph SBCPerimeter["Ring2All SBC Gateway (Public IP: 203.0.113.10)"]
Firewall["nftables + Pike Anti-Flood Shield"]
Kamailio["Kamailio 6.1+ SIP Signaling Engine
(Dispatcher Load Balancing, LCR, Topology Hiding)"]
RTPEngine["Sipwise RTPEngine 12.5+ Media Relay
(NAT Traversal, SRTP-to-RTP Transcoding)"]
SbcApi["SBC REST API (Fastify 5 :3003)"]
SbcWeb["Nginx Reverse Proxy & Admin Web UI (:443)"]
WGGateway["WireGuard Mesh Hub (wg0: 10.9.0.1)"]
end
subgraph PrivateCore["Private Core Network (Zero Public IP Exposure)"]
direction TB
FS1["Ring2All PBX Node 01
(wg0: 10.9.0.2 / LAN: 192.168.10.41)"]
FS2["Ring2All PBX Node 02
(wg0: 10.9.0.3 / LAN: 192.168.10.42)"]
BSS["Ring2All BSS (Real-Time OCS Engine)
(LAN: 192.168.10.50)"]
end
Subscribers -->|Public SIP :5060 / :5061| Firewall
Carriers -->|Public SIP :5060| Firewall
Subscribers -.->|Public Audio RTP 16384-32768| RTPEngine
Carriers -.->|Public Audio RTP 16384-32768| RTPEngine
Firewall --> Kamailio
Kamailio <--> RTPEngine
Kamailio <--> SbcApi
SbcWeb <--> SbcApi
Kamailio <-->|Encrypted SIP via wg0| WGGateway
WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS1
WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS2
Kamailio <-->|Sub-millisecond OCS Auth| BSS
```
### Core Responsibilities:
1. **Topology Hiding & Complete Shielding**: Internal FreeSWITCH PBX nodes have **zero public IP exposure**. They sit safely in private subnets, reachable only via encrypted WireGuard tunnels (`10.9.0.0/24`).
2. **High-Performance Media Relay (RTPEngine 12.5+)**: Seamlessly traverses aggressive symmetric NATs, bridges WebRTC (DTLS-SRTP) with legacy carrier RTP, and handles audio streams without CPU overhead.
3. **Perimeter Defense (Pike & nftables)**: Identifies and bans SIP brute-force scanners, floods, and malformed packets in real time.
4. **Dispatcher Load Balancing & LCR**: Evenly distributes SIP calls across the PBX cluster using round-robin or hash-based dispatchers with active SIP OPTIONS health-checks.
---
## ๐ฅ๏ธ System Requirements
| Specification | Minimum | Recommended | High Volume / Carrier |
| :--- | :--- | :--- | :--- |
| **Operating System** | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit |
| **CPU** | 4 vCPU | 8 vCPU | 16+ vCPU |
| **RAM** | 8 GB | 16 GB | 32 GB |
| **Storage** | 80 GB SSD | 160 GB NVMe | 300+ GB NVMe |
| **Network Interfaces** | 1 Public IPv4 + 1 Private LAN | 1 Public IPv4 + 1 Private LAN | 10 Gbps redundant NICs |
| **Concurrent Calls** | ~500 | ~2,500 | ~10,000+ |
---
## โก Option 1: Automated One-Touch Installation (Recommended)
Ring2All provides an automated one-touch installer that provisions Kamailio 6.1, RTPEngine 12.5, PostgreSQL 17, WireGuard VPN, Nginx reverse proxies, and the SBC management API in a single run.
Execute the following command as `root` on your clean Debian 13 server:
```bash
wget -O- https://repo.softswitchone.com/apt/install-sbc.sh | bash
```
### What the Automated Script Configures:
1. Installs base utilities (`curl`, `gnupg2`, `openssl`, `nginx`, `postgresql`, `wireguard`, `fail2ban`, `nftables`).
2. Registers the official Node.js 22 LTS runtime.
3. Installs Kamailio 6.1+ (`kamailio`, `kamailio-postgres-modules`, `kamailio-tls-modules`, `kamailio-websocket-modules`, `kamcli`).
4. Bootstraps the `kamailio` database schema and sets up default domains.
5. Installs the unified `softswitch-sbc` package from the Ring2All repository.
6. Deploys the Fastify-based REST API service (`sbc-api.service`) listening on loopback port `3003`.
7. Configures Nginx virtual host at `/etc/nginx/sites-available/softswitch-sbc` with TLS and WebSocket proxies.
8. Initializes the WireGuard VPN hub interface (`wg0` on `10.9.0.1/24`, UDP port `51820`).
9. Deploys secure `nftables` firewall rules protecting administrative ports while opening SIP and media ports.
---
## ๐ ๏ธ Option 2: Step-by-Step Manual Installation
If your infrastructure requires fine-grained control, follow this manual step-by-step process.
### Step 1: System Packages & Repositories
```bash
# Update and install base tools
apt-get update && apt-get install -y curl wget gnupg2 openssl nginx unixodbc odbc-postgresql fail2ban nftables wireguard
# Setup Node.js 22 LTS
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejs build-essential
# Add Ring2All Official Repository
curl -fsSL https://repo.softswitchone.com/apt/setup_repo | bash
apt-get update
```
### Step 2: Database Initialization
```bash
apt-get install -y postgresql-17
# Create SBC administrative database and user
sudo -u postgres psql << 'EOF'
CREATE DATABASE sbc_admin;
CREATE USER sbc_user WITH ENCRYPTED PASSWORD 'ChangeMeSecurely123!';
GRANT ALL PRIVILEGES ON DATABASE sbc_admin TO sbc_user;
ALTER DATABASE sbc_admin OWNER TO sbc_user;
EOF
```
### Step 3: Install Kamailio 6.1 & RTPEngine
```bash
# Install Kamailio core and modules
apt-get install -y kamailio kamailio-postgres-modules kamailio-tls-modules \
kamailio-websocket-modules kamailio-json-modules kamailio-presence-modules kamcli
# Install Sipwise RTPEngine
apt-get install -y rtpengine rtpengine-daemon rtpengine-iptables
```
Initialize the Kamailio PostgreSQL schema:
```bash
kamdbctl create
# Enter your PostgreSQL credentials when prompted to initialize 'kamailio' database.
```
### Step 4: Install Ring2All SBC Core Package
```bash
apt-get install -y -o Dpkg::Options::="--force-overwrite" softswitch-sbc
```
This installs:
- `/var/www/softswitch-sbc/api` (SBC Management REST API)
- `/var/www/softswitch-sbc/web` (React Administrative Web Console)
- `/etc/softswitch/sbc-api.env` (Environment variables)
- `/etc/systemd/system/sbc-api.service`
Enable and start the API service:
```bash
systemctl daemon-reload
systemctl enable --now sbc-api
systemctl status sbc-api
```
### Step 5: Nginx Reverse Proxy Configuration
Verify `/etc/nginx/sites-available/softswitch-sbc`:
```nginx
server {
listen 80;
server_name sbc.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name sbc.example.com;
ssl_certificate /etc/ssl/certs/softswitch-sbc.crt;
ssl_certificate_key /etc/ssl/private/softswitch-sbc.key;
# Static Web UI
root /var/www/softswitch-sbc/web;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
# SBC REST API
location /api/ {
proxy_pass http://127.0.0.1:3003/;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# Real-Time WebSocket Telemetry
location /ws {
proxy_pass http://127.0.0.1:3003/ws;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_read_timeout 86400;
}
}
```
Enable and reload:
```bash
ln -sf /etc/nginx/sites-available/softswitch-sbc /etc/nginx/sites-enabled/
nginx -t && systemctl reload nginx
```
---
## ๐ Connecting Core Telephony via WireGuard Mesh
In production multi-datacenter environments, your FreeSWITCH PBX nodes must **never be directly exposed to the public internet**. Instead, they connect to Ring2All SBC via an encrypted WireGuard VPN mesh.
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ RING2ALL SBC (Server Hub) โ
โ Public IP: 203.0.113.10 โ WireGuard IP: 10.9.0.1 โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
๐ WireGuard Transit (UDP 51820)
โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ RING2ALL PBX NODE (Client Spoke) โ
โ LAN Only: 192.168.10.41 โ WireGuard IP: 10.9.0.2 โ
โ FreeSWITCH bound to: local_ip_v4 = 10.9.0.2 โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
### Method A: Automated via Ring2All SBC Web UI (Recommended)
1. Log in to the SBC Web Console (`https://sbc.example.com`).
2. Navigate to **Network > WireGuard > Peers** and click **+ Add Peer**:
- **Peer Name**: `PBX-Node-01`
- **Assigned IP**: `10.9.0.2/32`
- **Allowed IPs**: `10.9.0.2/32`
3. Click **Generate Keys & Configuration**.
4. Download or copy the generated client configuration snippet.
5. On the FreeSWITCH PBX node, paste the content into `/etc/wireguard/wg0.conf`:
```bash
apt-get install -y wireguard
nano /etc/wireguard/wg0.conf
systemctl enable --now wg-quick@wg0
```
6. Verify tunnel connectivity from the PBX node:
```bash
ping 10.9.0.1
```
### Method B: Manual WireGuard Server Configuration
On the Ring2All SBC server, `/etc/wireguard/wg0.conf` should look like this:
```ini
[Interface]
Address = 10.9.0.1/24
ListenPort = 51820
PrivateKey =
PostUp = nft add rule inet filter input iifname "wg0" accept
PostDown = nft delete rule inet filter input iifname "wg0" accept
# PBX Node 01
[Peer]
PublicKey =
AllowedIPs = 10.9.0.2/32
# PBX Node 02
[Peer]
PublicKey =
AllowedIPs = 10.9.0.3/32
```
Restart WireGuard:
```bash
systemctl restart wg-quick@wg0
wg show
```
### WireGuard Audio Performance & Capacity
WireGuard executes as an in-kernel module (`wireguard.ko`) utilizing modern ChaCha20-Poly1305 cryptography. It delivers **3 to 5+ Gbps throughput** with near-zero CPU footprint:
- 1,000 simultaneous G.711 PCMU calls require only **~80 Mbps** and ~50,000 pps.
- WireGuard introduces **< 0.1 ms latency**, completely undetectable in voice audio quality.
---
## ๐ DNS & Cloudflare Architecture (Crucial)
When configuring DNS for Ring2All SBC, keep in mind that **Cloudflare standard proxy (Orange Cloud โ๏ธ๐งก) supports ONLY HTTP/HTTPS traffic. Cloudflare DOES NOT proxy UDP SIP traffic on port 5060**.
### 1. SIP Signaling DNS Records (Mandatory Grey Cloud โ๏ธ๐ฉถ)
For SIP registration and carrier trunking, you must create a DNS record with the **Cloudflare proxy disabled** (Grey Cloud โ๏ธ๐ฉถ) pointing directly to the SBC public IP:
| Type | Name | Content | Proxy Status | Purpose |
| :--- | :--- | :--- | :--- | :--- |
| **A** | `sbc.example.com` | `203.0.113.10` | **DNS Only (Grey Cloud โ๏ธ๐ฉถ)** | SIP UDP/TCP Signaling |
| **A** | `sip.example.com` | `203.0.113.10` | **DNS Only (Grey Cloud โ๏ธ๐ฉถ)** | Hardphone Registrar |
### 2. SIP Auto-Discovery via SRV Records (RFC 3263)
To enable zero-touch provisioning and allow phones to discover the SBC without typing port numbers:
```dns
_sip._udp.example.com. IN SRV 10 50 5060 sbc.example.com.
_sips._tcp.example.com. IN SRV 10 50 5061 sbc.example.com.
```
### 3. Web Admin Console DNS Records (Orange Cloud โ๏ธ๐งก)
The web administration interface can safely use Cloudflare's CDN and WAF (Orange Cloud โ๏ธ๐งก):
| Type | Name | Content | Proxy Status | Purpose |
| :--- | :--- | :--- | :--- | :--- |
| **CNAME** | `sbc-admin.example.com` | `sbc.example.com` | **Proxied (Orange Cloud โ๏ธ๐งก)** | Web Dashboard & WAF |
---
## ๐ Verification & Health Checks
Run these commands to verify that Ring2All SBC is operating correctly:
### 1. Service Status
```bash
systemctl status kamailio
systemctl status rtpengine
systemctl status sbc-api
systemctl status nginx
systemctl status wg-quick@wg0
```
### 2. Local API Health Check
```bash
curl -s http://127.0.0.1:3003/health
# Expected: {"status":"ok","service":"sbc-api","version":"1.0.0"}
```
### 3. Active Port Listeners
```bash
ss -ulnp | grep -E '5060|51820'
# Expected: Kamailio listening on 0.0.0.0:5060 and 10.9.0.1:5060; WireGuard on 0.0.0.0:51820
```
### 4. Kamailio Runtime Inspection
```bash
# Check loaded modules
kamcmd system.listMethods
# Check dispatcher status (PBX cluster nodes)
kamcmd dispatcher.list
# Inspect active RTPEngine media sessions
rtpengine-ctl list sessions
```
---
## ๐ง Production Troubleshooting
### 1. Phones fail to register with "Request Timeout (408)"
- **Cause**: DNS is pointing through Cloudflare Orange Cloud (which drops UDP port 5060) or `nftables` is dropping inbound SIP packets.
- **Solution**: Set DNS record to **Grey Cloud (DNS Only)** in Cloudflare. Check firewall rules:
```bash
nft list ruleset | grep 5060
```
### 2. One-Way Audio on Calls Traversing SBC
- **Cause**: RTPEngine is advertising an internal IP instead of the public IP in SDP headers.
- **Solution**: Verify `/etc/rtpengine/rtpengine.conf` interface configuration:
```ini
interface = external/203.0.113.10;internal/10.9.0.1
```
Ensure RTP port range `16384-32768/udp` is permitted through the cloud security group.
---
## ๐ Next Steps
- **[Web Cluster & Load Balancing Guide](web-cluster-load-balancing.md)**: Scale your frontend interfaces.
- **[Distributed PBX Cluster Guide](distributed-cluster.md)**: Scale out N+1 FreeSWITCH telephony nodes behind this SBC.
- **[Ring2All BSS Deployment](bss-deployment.md)**: Connect carrier billing, OCS rating, and customer self-care portals.